mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sriram Nambakam <snambakam@linux.microsoft.com>
To: kvm@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [RFC PATCH v1 29/42] init/vm_planes: set up planes from rootfs_initcall and load ELF payloads
Date: Wed,  5 Aug 2026 04:03:11 -0700	[thread overview]
Message-ID: <20260805110324.25067-30-snambakam@linux.microsoft.com> (raw)
In-Reply-To: <20260805110324.25067-1-snambakam@linux.microsoft.com>

Move plane setup out of start_kernel()/kernel_init_freeable() and into a
self-registering rootfs_initcall. Link vm_planes.o after initramfs.o so
populate_rootfs() has unpacked the initramfs (which carries the
config-vm-planes file and the plane kernels) before arch_init_vm_planes()
runs. arch_init_vm_planes() becomes static and no longer needs a
declaration in vm_planes.h.

Also load the plane kernels as ELF payloads, copying loadable segments
into the reserved plane memory and zeroing the BSS, replacing the
early_ioremap path with a plain io.h mapping.

Signed-off-by: Sriram Nambakam <snambakam@linux.microsoft.com>
---
 include/linux/vm_planes.h |  1 -
 init/Kconfig              |  5 ++-
 init/Makefile             |  5 ++-
 init/main.c               |  4 --
 init/vm_planes.c          | 88 +++++++++++++++++++++------------------
 5 files changed, 54 insertions(+), 49 deletions(-)

diff --git a/include/linux/vm_planes.h b/include/linux/vm_planes.h
index 1130557cf5aa..e33fa03d1d4a 100644
--- a/include/linux/vm_planes.h
+++ b/include/linux/vm_planes.h
@@ -25,7 +25,6 @@ struct vm_plane_config {
 	char cmdline[VM_PLANE_CMDLINE_MAX];
 };
 
-void __init arch_init_vm_planes(void);
 int __init load_vm_plane_kernels(unsigned int plane_count,
 				 struct vm_plane_config *plane_cfg);
 
diff --git a/init/Kconfig b/init/Kconfig
index 23d9cca334ba..5d76fe852376 100644
--- a/init/Kconfig
+++ b/init/Kconfig
@@ -1720,8 +1720,9 @@ config VM_PLANES
 	  Enable hypervisor enabled multi-kernel support.
 
 	  This allows processing the kernel command-line parameter
-	  "enable-vm-planes" and, when requested, calling
-	  arch_init_vm_planes() during start_kernel().
+	  "enable-vm-planes" and, when requested, setting up the configured
+	  planes from a rootfs_initcall (after the initramfs is populated and
+	  before device drivers and late_initcalls run).
 
 	  The initrd config-vm-planes file is expected to provide per-plane
 	  entries for PLANE_<id>_KERNEL, PLANE_<id>_LOAD_OFFSET, and
diff --git a/init/Makefile b/init/Makefile
index 113133c8cdd7..f6ac312f1e98 100644
--- a/init/Makefile
+++ b/init/Makefile
@@ -6,12 +6,15 @@
 ccflags-y := -fno-function-sections -fno-data-sections
 
 obj-y                          := main.o version.o mounts.o
-obj-y                          += vm_planes.o
 ifneq ($(CONFIG_BLK_DEV_INITRD),y)
 obj-y                          += noinitramfs.o
 else
 obj-$(CONFIG_BLK_DEV_INITRD)   += initramfs.o
 endif
+# vm_planes.o must link AFTER initramfs.o so that, at rootfs_initcall level,
+# populate_rootfs() (which unpacks the initramfs) runs before
+# arch_init_vm_planes() reads the plane config and kernels from the rootfs.
+obj-y                          += vm_planes.o
 obj-$(CONFIG_GENERIC_CALIBRATE_DELAY) += calibrate.o
 obj-$(CONFIG_INITRAMFS_TEST)   += initramfs_test.o
 
diff --git a/init/main.c b/init/main.c
index 1c779f6d60cc..be188e67c556 100644
--- a/init/main.c
+++ b/init/main.c
@@ -1663,10 +1663,6 @@ static noinline void __init kernel_init_freeable(void)
 	wait_for_initramfs();
 	console_on_rootfs();
 
-#ifdef CONFIG_VM_PLANES
-	arch_init_vm_planes();
-#endif
-
 	/*
 	 * check if there is an early userspace init.  If yes, let it do all
 	 * the work
diff --git a/init/vm_planes.c b/init/vm_planes.c
index 10c7facdb1af..64d5ff19a736 100644
--- a/init/vm_planes.c
+++ b/init/vm_planes.c
@@ -12,9 +12,9 @@
 #include <linux/vm_planes.h>
 #include <linux/elf.h>
 #include <linux/mm.h>
+#include <linux/io.h>
 #include <asm/cpu.h>
 #include <asm/kvm_para.h>
-#include <asm-generic/early_ioremap.h>
 
 #ifdef CONFIG_VM_PLANES
 static bool __initdata enable_vm_planes_requested;
@@ -360,44 +360,29 @@ static int __init vm_planes_get_cfg(unsigned int *plane_count,
 static int __init copy_to_early_mem(phys_addr_t dest, const void *src,
 				    unsigned long size)
 {
-	unsigned long slop, clen;
-	char *p;
-
-	while (size) {
-		slop = offset_in_page(dest);
-		clen = size;
-		if (clen > PAGE_SIZE - slop)
-			clen = PAGE_SIZE - slop;
-		p = early_memremap(dest & PAGE_MASK, clen + slop);
-		if (!p)
-			return -ENOMEM;
-		memcpy(p + slop, src, clen);
-		early_memunmap(p, clen + slop);
-		dest += clen;
-		src += clen;
-		size -= clen;
-	}
+	void *p;
+
+	if (!size)
+		return 0;
+	p = memremap(dest, size, MEMREMAP_WB);
+	if (!p)
+		return -ENOMEM;
+	memcpy(p, src, size);
+	memunmap(p);
 	return 0;
 }
 
 static int __init zero_early_mem(phys_addr_t dest, unsigned long size)
 {
-	unsigned long slop, clen;
-	char *p;
-
-	while (size) {
-		slop = offset_in_page(dest);
-		clen = size;
-		if (clen > PAGE_SIZE - slop)
-			clen = PAGE_SIZE - slop;
-		p = early_memremap(dest & PAGE_MASK, clen + slop);
-		if (!p)
-			return -ENOMEM;
-		memset(p + slop, 0, clen);
-		early_memunmap(p, clen + slop);
-		dest += clen;
-		size -= clen;
-	}
+	void *p;
+
+	if (!size)
+		return 0;
+	p = memremap(dest, size, MEMREMAP_WB);
+	if (!p)
+		return -ENOMEM;
+	memset(p, 0, size);
+	memunmap(p);
 	return 0;
 }
 
@@ -616,23 +601,41 @@ int __init __weak alloc_vm_planes(unsigned int plane_count,
 int __init __weak activate_vm_planes(unsigned int plane_count,
 				      struct vm_plane_config *plane_cfg) { return -ENOSYS; }
 
-void __init arch_init_vm_planes(void)
+/*
+ * Set up VM planes during boot.
+ *
+ * This must run after the initramfs is populated (it reads the plane config
+ * and plane kernels from the rootfs) and, crucially, *before* any consumer
+ * that issues a plane switch -- in particular the VBS backend init/seal, and
+ * before any device driver, module, or userspace can touch a plane.  A
+ * rootfs_initcall satisfies all of these: it runs immediately after
+ * populate_rootfs() (initramfs ready) and before every device_initcall and
+ * late_initcall.  Because init/ links before security/, this also runs before
+ * the VBS probe/HEKI rootfs_initcalls, so the secure plane vcpu exists by the
+ * time the first VTL call is issued.
+ */
+static int __init arch_init_vm_planes(void)
 {
 	unsigned int plane_count = VM_PLANES_DEFAULT_COUNT;
 	struct vm_plane_config *plane_cfg;
 	int ret;
 
 	if (!enable_vm_planes_requested)
-		return;
+		return 0;
 
-	if (!kvm_para_available())
-		return;
+	/* Ensure any asynchronous initramfs unpacking has completed. */
+	wait_for_initramfs();
+
+	if (!kvm_para_available()) {
+		pr_info("vm_planes: KVM paravirt unavailable, skipping plane setup\n");
+		return 0;
+	}
 
 	ret = vm_planes_get_cfg(&plane_count, &plane_cfg);
 	if (ret) {
 		pr_warn("vm_planes: failed to parse %s: %d\n",
 			VM_PLANES_CONFIG_FILE, ret);
-		return;
+		return 0;
 	}
 
 	pr_info("vm_planes: enabling %u planes (ids 0..%u)\n",
@@ -641,18 +644,21 @@ void __init arch_init_vm_planes(void)
 	ret = alloc_vm_planes(plane_count, plane_cfg);
 	if (ret) {
 		pr_err("vm_planes: failed to allocate planes: %d\n", ret);
-		return;
+		return 0;
 	}
 
 	ret = load_vm_plane_kernels(plane_count, plane_cfg);
 	if (ret) {
 		pr_err("vm_planes: failed to load plane kernels: %d\n", ret);
-		return;
+		return 0;
 	}
 
 	ret = activate_vm_planes(plane_count, plane_cfg);
 	if (ret)
 		pr_err("vm_planes: failed to activate planes: %d\n", ret);
+
+	return 0;
 }
+rootfs_initcall(arch_init_vm_planes);
 
 #endif /* CONFIG_VM_PLANES */
-- 
2.55.0


  parent reply	other threads:[~2026-08-05 11:04 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-05 11:02 [RFC PATCH v1 00/42] VBS/VSM-on-KVM: VBS integration for KVM VM planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 01/42] Fix merge issue - Remove duplicate definition for kvm_arch_has_irq_bypass Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 02/42] Fix compilation Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 03/42] Fix compile error Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 04/42] Fix compile errors Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 05/42] Initial support for VM Planes - Add kernel config for CONFIG_VM_PLANES - Parse vm plane config from initrd for plane configuration - Make hypercalls to allocate memory for the vm planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 06/42] Use vcpu count from the plane configuration Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 07/42] skip processing plane configuration for plane 0 - plane 0 is the boot plane Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 08/42] Add plane config param to specify kernel image format Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 09/42] Activate the VM Planes through the Hypervisor - Using KVM as the VMM Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 10/42] allow the command line to be specified for kernels in other planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 11/42] Various changes to support VM Planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 12/42] Add a Virtualization Based Security (VBS) framework. - Add backends for AMD SEV-SNP, Intel TDX, Arm CCA and KVM Planes. - Support VTL on Hyper-V in addition to Planes on KVM Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 13/42] Add a inter-plane communication mechanism through KVM. - model this to use a single page similar to SEV-SNP Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 14/42] KVM: Add per-plane memory attribute support for cross-plane EPT protection Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 15/42] KVM: x86: Add KVM_HC_VBS_VTL_CALL hypercall for VBS inter-plane calls Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 16/42] vbs: Add HEKI kernel sealing and fix KVM plane memory attribute guards Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 17/42] vbs: Add module authentication via VBS/HEKI Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 18/42] vbs: Add kexec validation and make module auth non-fatal Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 19/42] Merge branch 'master' into vm-planes Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 20/42] kvm: x86: fix merged plane API/stat build regressions Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 21/42] KVM: x86: exit VM planes and VBS hypercalls to userspace Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 22/42] kexec: block legacy kexec_load when VBS is active Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 23/42] kvm: x86: fix merged plane API/stat build regressions Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 24/42] KVM: planes: expose memory-attribute setting to in-kernel callers Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 25/42] vm_planes: drop unused per-plane vcpu_count Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 26/42] drivers/virt: add VBS secure-plane park loop Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 27/42] KVM: planes: add arch-neutral in-kernel plane switch helper Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 28/42] KVM: x86: add VBS VTL call/return and cross-plane set-mem-attrs hypercalls Sriram Nambakam
2026-08-05 11:03 ` Sriram Nambakam [this message]
2026-08-05 11:03 ` [RFC PATCH v1 30/42] security/vbs: run backend probe and HEKI seal at rootfs_initcall Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 31/42] security/vbs: pin the VTL call hypercall to CPU0 Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 32/42] security/vbs: add secure-plane monitor backend Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 33/42] drivers/virt: rename VBS park loop to secure_monitor Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 34/42] x86/realmode: skip the sub-1M trampoline for the VBS secure plane Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 35/42] KVM: x86: deny normal-plane access to secure-plane memory Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 36/42] KVM: plane: handle KVM_CHECK_EXTENSION on the plane fd Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 37/42] KVM: selftests: run plane tests with a split IRQ chip Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 38/42] kvm: x86: drop obsolete kvm_cache_regs.h Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 39/42] kvm: arch: finalize plane hooks and kvm_arch_vcpu_create signature Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 40/42] kvm: x86: use kvm_vcpu scheduling-state accessors and struct stat fields Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 41/42] kvm: x86: finalize per-plane APIC state and CPUID placement Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 42/42] kvm: planes: reconcile core plane state, UAPI and hypercall exit Sriram Nambakam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260805110324.25067-30-snambakam@linux.microsoft.com \
    --to=snambakam@linux.microsoft.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®